Junglewise Threat Intelligence

CVE-2026-48367: Adobe After Effects out-of-bounds write via malicious file

CVE-2026-48367 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Adobe After Effects. Vendors: Adobe.

Executive brief

Adobe After Effects, a professional video editing and visual effects application, is vulnerable to a security flaw when processing specially crafted files. If a user is tricked into opening a malicious file, an attacker could gain the ability to run unauthorized commands or take control of the user's computer. This could lead to the theft of sensitive project data or a complete compromise of the workstation.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in Adobe After Effects. The flaw is triggered when the application parses a specifically crafted malicious file, leading to memory corruption. An attacker can leverage this to execute arbitrary code with the privileges of the current user. The attack vector is local, requiring user interaction to open the file. Adobe has addressed this in versions 26.3 and 25.6.6.

Affected products

  • Adobe After Effects <= 26.2.1, <= 25.6.5

Timeline

  • 2026-07-14: advisory: Adobe published security bulletin APSB26-78
  • 2026-07-14: disclosed

References

Related threats